CVE-2019-16319Infinite Loop in Wireshark

CWE-835Infinite Loop7 documents6 sources
Severity
7.5HIGHNVD
EPSS
0.7%
top 27.94%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateMay 24

Description

In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go into an infinite loop. This was addressed in plugins/epan/gryphon/packet-gryphon.c by checking for a message length of zero.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/wireshark< wireshark 3.0.4-1 (bookworm)
Debianwireshark/wireshark< 3.0.4-1+3
NVDwireshark/wireshark2.6.02.6.10+1
NVDopensuse/leap15.1

Also affects: Debian Linux 9.0

🔴Vulnerability Details

2
GHSA
GHSA-fmr6-8ggw-wc56: In Wireshark 32022-05-24
OSV
CVE-2019-16319: In Wireshark 32019-09-15

📋Vendor Advisories

2
Red Hat
wireshark: gryphon dissector infinite loop (wnpa-sec-2019-21)2019-08-25
Debian
CVE-2019-16319: wireshark - In Wireshark 3.0.0 to 3.0.3 and 2.6.0 to 2.6.10, the Gryphon dissector could go ...2019

💬Community

2
Bugzilla
CVE-2019-16319 wireshark: gryphon dissector infinite loop (wnpa-sec-2019-21) [fedora-all]2019-11-21
Bugzilla
CVE-2019-16319 wireshark: gryphon dissector infinite loop (wnpa-sec-2019-21)2019-11-21